index.php in LEMON-S PHP Simple Oekaki BBS prior to 1.21 allows remote malicious users to delete arbitrary files via the oekakis parameter.
lemon-s php simple oekaki